Confirmed breach. Intrusion Oct 21, 2024, discovered Oct 21, 2024 — the first regulatory filing landed 10 days later. 1 individuals reported across the linked filings.
Kestra Financial, Inc. reported a phishing incident on Oct 31, 2024, affecting 1 New Hampshire resident. Employees received a malicious email redirecting to a fraudulent Microsoft login, compromising credentials. One file containing client PII was exfiltrated. Kestra revoked sessions, reset passwords, and offered credit monitoring.
Kestra Financial Services, a financial services firm based in Austin, TX, reported a data breach to the Maine AG occurring on October 21, 2024, and discovered the same day. The breach type was described as 'Other' with no further technical specifics disclosed. A total of 196 individuals were affected, including 1 Maine resident. Written notification was sent on November 8, 2024, and 12 months of identity theft protection services were offered.
Affected (this filing): 1
ME AG ≤30d · 10d
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.